Proof-Carrying Network Code

Proof-Carrying Network Code
复制标题

DOI:
10.1145/3319535.3363214
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
C. Skalka;J. Ring;David Darais;Minseok Kwon;Sahil Gupta;Kyle I. Diller;S. Smolka;Nate Foster
C. Skalka;J. Ring;David Darais;Minseok Kwon;Sahil Gupta;Kyle I. Diller;S. Smolka;Nate Foster
中科院分区:
其他
文献类型:
--
作者:
C. Skalka;J. Ring;David Darais;Minseok Kwon;Sahil Gupta;Kyle I. Diller;S. Smolka;Nate Foster

文献摘要

被引文献

相似文献

计算机网络通常是针对恶意攻击的第一道防线。尽管在软件定义网络(SDN)中定义和执行安全策略的工具越来越多,但大多数人都采用单个控制点,并且无法应付具有多个管理域的网络中出现的挑战。例如,消费者可能希望允许设备供应商配置其家用IoT网络,这引起了安全性和隐私问题。在本文中,我们提出了一个称为证明携带网络代码(PCNC)的框架,用于在具有交互管理域的SDN中指定和执行安全性。像携带证明授权(PCA)一样,PCNC提供了管理授权域的方法,以及携带证明代码(PCC),PCNC提供了用于强制网络程序行为属性的方法。我们为PCNC开发了理论基础,并在模拟和真实的网络设置中对其进行了评估,其中包括一项案例研究,该案例研究考虑了用于家庭健康监测的物联网网络中的安全性。
Computer networks often serve as the first line of defense against malicious attacks. Although there are a growing number of tools for defining and enforcing security policies in software-defined networks (SDNs), most assume a single point of control and are unable to handle the challenges that arise in networks with multiple administrative domains. For example, consumers may want want to allow their home IoT networks to be configured by device vendors, which raises security and privacy concerns. In this paper we propose a framework called Proof-Carrying Network Code (PCNC) for specifying and enforcing security in SDNs with interacting administrative domains. Like Proof-Carrying Authorization (PCA), PCNC provides methods for managing authorization domains, and like Proof-Carrying Code (PCC), PCNC provides methods for enforcing behavioral properties of network programs. We develop theoretical foundations for PCNC and evaluate it in simulated and real network settings, including a case study that considers security in IoT networks for home health monitoring.